Where Are Industrial Control System Flaws Found?

TL;DR
Most identified industrial control system vulnerabilities were found in the presentation and control layer, particularly HMIs, rather than in sensors or PLCs. The study recommends addressing familiar IT weaknesses through patching, password management, secure configuration, staff training, software maintenance, and comprehensive vulnerability and risk management audits aligned with applicable industry security standards.
Transcript
Hello and welcome to this, uh, preview session for upcoming RSA Conference Two Thousand Fifteen on Industrial Control System Vulnerability Trends. My name is Amol, and, uh, I'm Director of Vulnerability Labs at Qualys. So, uh, what are industrial control systems? These are systems that, uh, are everywhere around us. They could be carrying power to ... Read More
Key Insights
- Industrial control systems support physical operations such as power delivery, car manufacturing, smaller manufacturing plants, and dam control, so vulnerabilities can affect systems that perform essential monitoring and operational functions.
- Historical ICS vulnerability totals may understate the actual problem because tracking was not accurate in earlier years. The low reported numbers for 2009 and 2010 reflected weak tracking mechanisms, not an absence of vulnerabilities.
- Industrial control systems commonly contain four functional areas: data acquisition, data conversion, communication, and presentation or control. This shared structure provides a practical framework for examining vulnerabilities across otherwise different systems.
- Data acquisition components include sensors, meters, and field devices that collect measurements such as temperature and pressure. Vulnerabilities at this stage can affect the equipment responsible for gathering information from industrial processes.
- Data conversion components include PLCs, IEDs, and RTUs that carry collected data through communication channels to a SCADA master or HMI. Vulnerabilities in these devices could permit potential attackers to gain partial or complete control of a system.
- Communication vulnerabilities were found in technologies including DNP3, SSL, and HTTPS during the 2014 and 2015 timeframe. DNP3 was the most frequently observed communication component among the examples discussed in the presentation preview.
- Presentation and control vulnerabilities represented a reported 63 percent of the findings, compared with 21 percent in communication and about 14 percent in PLCs and IEDs. The concentration in the HMI layer surprised researchers who expected more weaknesses in sensors and PLCs.
- Practical ICS risk reduction includes patching, stronger password management, secure configuration, security training for engineers and administrators, maintenance of operating systems and other commercial software, and comprehensive vulnerability and risk management audits aligned with industry standards.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What are industrial control systems used for?
Industrial control systems operate or support physical and industrial processes found throughout critical infrastructure and manufacturing. The examples provided include systems that carry power to homes, manufacture cars, run small or medium-scale manufacturing plants, and control dams. Although their specific purposes differ, these systems commonly acquire physical data, convert it, communicate it, and present information for operational control.
Q: What are the main components of an industrial control system?
An industrial control system commonly consists of four functional components: data acquisition, data conversion, communication, and presentation or control. Acquisition devices gather process measurements, conversion equipment carries or processes the collected data, communication channels transmit it, and systems such as a SCADA master or HMI present information and support control activities. These shared components provide a structure for vulnerability analysis.
Q: Why were few ICS vulnerabilities reported in 2009 and 2010?
The low reported vulnerability numbers in 2009 and 2010 did not mean industrial control systems lacked security flaws. ICS vulnerability research and reporting were still relatively new, and accurate tracking mechanisms were not available. Consequently, earlier totals may reflect incomplete visibility and weak reporting practices rather than the true number of vulnerabilities present in industrial environments at that time.
Q: Where were most industrial control system vulnerabilities found?
Most vulnerabilities in the study were found in the presentation and control area, particularly the HMI layer. This category represented a reported 63 percent of the findings. Communication accounted for 21 percent, while vulnerabilities in PLCs and IEDs represented about 14 percent. The result surprised researchers because they had expected more weaknesses in sensors, PLCs, and similar industrial devices.
Q: What security flaws affect industrial HMIs?
Industrial HMIs can contain vulnerabilities resembling those regularly encountered in conventional IT infrastructure. Examples identified in the presentation include web application weaknesses, thin-client vulnerabilities, cross-site scripting, SQL injection, and directory traversal. Their presence shows that protecting industrial environments requires attention not only to specialized control equipment, but also to familiar application and software security problems in the presentation layer.
Q: How can PLC and IED vulnerabilities affect control systems?
PLCs and IEDs are data conversion components that help carry collected process data through communication channels to a SCADA master or HMI. Vulnerabilities in these devices could allow potential attackers to obtain partial or complete control of an industrial system. Although the study found fewer flaws in PLCs and IEDs than in the presentation layer, their possible operational consequences remain significant.
Q: What communication technologies had ICS vulnerabilities?
The communication vulnerabilities reviewed from the 2014 and 2015 timeframe affected several types of components and technologies. DNP3 was the most frequently observed communication component in the examples, followed by SSL and HTTPS. These findings place communication alongside data acquisition, data conversion, and presentation or control as an area that should be included in industrial control system security assessments.
Q: How can organizations reduce industrial control system risk?
Organizations can reduce industrial control system risk through patching, password management, secure configuration, and security training for engineers, technicians, and administrators. They should also patch commercial software used in the environment, including operating systems, databases, and web servers. A comprehensive vulnerability and risk management audit, combined with compliance with relevant industry security standards, provides a broader remediation framework.
Summary & Key Takeaways
-
Industrial control systems support critical and industrial operations, including power delivery, vehicle manufacturing, smaller manufacturing plants, and dams. Although individual systems differ, they commonly contain four functional components: data acquisition, data conversion, communication, and presentation or control. Each component can introduce vulnerabilities with consequences for system operation and security.
-
The study found that presentation and control systems contained the largest reported share of vulnerabilities. Many involved HMIs and resembled ordinary IT security flaws, including cross-site scripting, SQL injection, and directory traversal. Communication weaknesses involved components such as DNP3, SSL, and HTTPS, while fewer vulnerabilities appeared in PLCs and IEDs.
-
Industrial control system security is difficult because some systems are connected to or exposed on the Internet, while older equipment was designed primarily for performance rather than security. Recommended improvements include patching, password management, configuration reviews, staff training, maintenance of commercial software, comprehensive risk audits, and compliance with relevant industry standards.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator